CVE Feed

    Dashboard / CVE / CVE-2026-75140

    CVE-2026-75140

    jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.

    Published:Aug 20, 2026
    Last Modified:Aug 21, 2026
    EPS:Aug 20, 2026
    EPSS Score:0.00525
    CVSS Score:7.5

    Affected Products

    Vendor
    Jhy
    Product
    Jsoup

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High